CVEs from 2018

3,844 normalized CVEs published or assigned in this year.

Total
3,844
critical
critical 225
high
high 266
medium
medium 224
low
low 32
% Critical
5.9%
% with KEV
2.3%
% with exploit
2.4%

Top products

  • erpnext 4
  • terminal_services_manager 1
  • ultraiso 1
  • dolibarr_erp\/crm 1
  • gitbucket 1
  • pdfunite 1
  • qemu 1
  • virtualization_manager 1
0
KEVHas exploit
Reset
CVE Severity CVSS Risk Published Description Impact
CVE-2018-17463 critical 10.0 4y ago multiple issues in chromium arch
CVE-2018-17480 critical 10.0 4y ago multiple issues in chromium archdebian
CVE-2018-7602 critical 10.0 8y ago A remote code execution vulnerability exists within multiple subsystems of Drupal that can allow attackers to exploit multiple attack vectors on a Drupal site. archphp
CVE-2018-7600 critical 10.0 8y ago Drupal Core contains a remote code execution vulnerability that could allow an attacker to exploit multiple attack vectors on a Drupal site, resulting in complete site compromise. archphp
CVE-2018-25357 critical 9.8 9.8 5d ago Dolibarr ERP CRM 7.0.3 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary code by injecting PHP code through the db_name parameter. Attackers ca…
CVE-2018-25350 critical 9.8 9.8 5d ago userSpice 4.3.24 contains a username enumeration vulnerability that allows unauthenticated attackers to discover valid usernames by sending POST requests to the existingUsernameCheck.php endpoint. At…
CVE-2018-25335 critical 9.8 9.8 11d ago WordPress Plugin Peugeot Music 1.0 contains an arbitrary file upload vulnerability that allows unauthenticated attackers to upload malicious files by sending POST requests to the upload.php endpoint.…
CVE-2018-25332 critical 9.8 9.8 11d ago GitBucket 4.23.1 contains an unauthenticated remote code execution vulnerability that allows attackers to execute arbitrary commands by exploiting weak secret token generation and insecure file uploa…
CVE-2018-25320 critical 9.8 9.8 11d ago ACL Analytics versions 11.x through 13.0.0.579 contain an arbitrary code execution vulnerability that allows attackers to execute arbitrary commands by leveraging the EXECUTE function. Attackers can …
CVE-2018-25318 critical 9.8 9.8 28d ago Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers ca…
CVE-2018-25317 critical 9.8 9.8 28d ago Tenda W3002R/A302/W309R wireless routers version V5.07.64_en contain a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient se…
CVE-2018-25316 critical 9.8 9.8 28d ago Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send…
CVE-2018-25272 critical 9.8 9.8 1mo ago ELBA5 5.8.0 contains a remote code execution vulnerability that allows attackers to obtain database credentials and execute arbitrary commands with SYSTEM level permissions. Attackers can connect to …
CVE-2018-5162 critical 9.5 Plaintext of decrypted emails can leak through the src attribute of remote images, or links. This vulnerability affects Thunderbird ESR < 52.8 and Thunderbird < 52.8. archdebian
CVE-2018-18492 critical 9.5 A use-after-free vulnerability can occur after deleting a selection element due to a weak reference to the select element in the options collection. This results in a potentially exploitable crash. T… archsusedebian
CVE-2018-5183 critical 9.5 Mozilla developers backported selected changes in the Skia library. These changes correct memory corruption issues including invalid buffer reads and writes during graphic operations. This vulnerabil… archdebian
CVE-2018-11354 critical 9.5 In Wireshark 2.6.0, the IEEE 1905.1a dissector could crash. This was addressed in epan/dissectors/packet-ieee1905.c by making a certain correction to string handling. archsusedebian
CVE-2018-5173 critical 9.5 The filename appearing in the "Downloads" panel improperly renders some Unicode characters, allowing for the file name to be spoofed. This can be used to obscure the file extension of potentially exe… archdebian
CVE-2018-5166 critical 9.5 WebExtensions can use request redirection and a "filterReponseData" filter to bypass host permission settings to redirect network traffic and access content from a host for which they do not have exp… archdebian
CVE-2018-6105 critical 9.5 multiple issues in chromium arch
CVE-2018-12361 critical 9.5 An integer overflow can occur in the SwizzleData code while calculating buffer sizes. The overflowed value is used for subsequent graphics computations when their inputs are not sanitized which resul… archsusedebian
CVE-2018-17481 critical 9.5 multiple issues in chromium archdebian
CVE-2018-6112 critical 9.5 multiple issues in chromium arch
CVE-2018-11233 critical 9.5 In Git before 2.13.7, 2.14.x before 2.14.4, 2.15.x before 2.15.2, 2.16.x before 2.16.4, and 2.17.x before 2.17.1, code to sanity-check pathnames on NTFS can result in reading out-of-bounds memory. archdebian
CVE-2018-5181 critical 9.5 If a URL using the "file:" protocol is dragged and dropped onto an open tab that is running in a different child process the tab will open a local file corresponding to the dropped URL, contrary to p… archdebian
CVE-2018-6113 critical 9.5 multiple issues in chromium arch
CVE-2018-5177 critical 9.5 A vulnerability exists in XSLT during number formatting where a negative buffer size may be allocated in some instances, leading to a buffer overflow and crash if it occurs. This vulnerability affect… archdebian
CVE-2018-19626 critical 9.5 In Wireshark 2.6.0 to 2.6.4 and 2.4.0 to 2.4.10, the DCOM dissector could crash. This was addressed in epan/dissectors/packet-dcom.c by adding '\0' termination. archsusedebian
CVE-2018-18340 critical 9.5 multiple issues in chromium archdebian
CVE-2018-10933 critical 9.5 A vulnerability was found in libssh's server-side state machine before versions 0.7.6 and 0.8.4. A malicious client could create channels without first performing authentication, resulting in unautho… archsusedebian
CVE-2018-5167 critical 9.5 The web console and JavaScript debugger do not sanitize all output that can be hyperlinked. Both will display "chrome:" links as active, clickable hyperlinks in their output. Web sites should not be … archdebian
CVE-2018-12383 critical 9.5 If a user saved passwords before Firefox 58 and then later set a master password, an unencrypted copy of these passwords is still accessible. This is because the older stored password file was not de… archdebian
CVE-2018-1000222 critical 9.5 Libgd version 2.2.5 contains a Double Free Vulnerability vulnerability in gdImageBmpPtr Function that can result in Remote Code Execution . This attack appear to be exploitable via Specially Crafted … archsusedebian
CVE-2018-19876 critical 9.5 cairo 1.16.0, in cairo_ft_apply_variations() in cairo-ft-font.c, would free memory using a free function incompatible with WebKit's fastMalloc, leading to an application crash with a "free(): invalid… archdebian
CVE-2018-10529 critical 9.5 An issue was discovered in LibRaw 0.18.9. There is an out-of-bounds read affecting the X3F property table list implementation in libraw_x3f.cpp and libraw_cxx.cpp. archdebian
CVE-2018-12359 critical 9.5 A buffer overflow can occur when rendering canvas content while adjusting the height and width of the canvas element dynamically, causing data to be written outside of the currently computed boundari… archsusedebian
CVE-2018-18500 critical 9.5 A use-after-free vulnerability can occur while parsing an HTML5 stream in concert with custom HTML elements. This results in the stream parser object being freed while still in use, leading to a pote… archsusedebian
CVE-2018-5145 critical 9.5 Memory safety bugs were reported in Firefox ESR 52.6. These bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to run arbitrary cod… archsusedebian
CVE-2018-6087 critical 9.5 multiple issues in chromium arch
CVE-2018-6092 critical 9.5 multiple issues in chromium arch
CVE-2018-12403 critical 9.5 If a site is loaded over a HTTPS connection but loads a favicon resource over HTTP, the mixed content warning is not displayed to users. This vulnerability affects Firefox < 63. archsusedebian
CVE-2018-6085 critical 9.5 multiple issues in chromium arch
CVE-2018-18646 critical 9.5 multiple issues in gitlab arch
CVE-2018-5169 critical 9.5 If manipulated hyperlinked text with "chrome:" URL contained in it is dragged and dropped on the "home" icon, the home page can be reset to include a normally-unlinkable chrome page as one of the hom… archdebian
CVE-2018-6109 critical 9.5 multiple issues in chromium arch
CVE-2018-6093 critical 9.5 multiple issues in chromium arch
CVE-2018-5160 critical 9.5 WebRTC can use a "WrappedI420Buffer" pixel buffer but the owning image object can be freed while it is still in use. This can result in the WebRTC encoder using uninitialized memory, leading to a pot… archdebian
CVE-2018-17465 critical 9.5 multiple issues in chromium arch
CVE-2018-17470 critical 9.5 multiple issues in chromium arch
CVE-2018-12366 critical 9.5 An invalid grid size during QCMS (color profile) transformations can result in the out-of-bounds read interpreted as a float value. This could leak private data into the output. This vulnerability af… archsusedebian
CVE-2018-12376 critical 9.5 Memory safety bugs present in Firefox 61 and Firefox ESR 60.1. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploited to … archsusedebian
CVE-2018-12379 critical 9.5 When the Mozilla Updater opens a MAR format file which contains a very long item filename, an out-of-bounds write can be triggered, leading to a potentially exploitable crash. This requires running t… archsusedebian
CVE-2018-5125 critical 9.5 Memory safety bugs were reported in Firefox 58 and Firefox ESR 52.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could be exploit… archsusedebian
CVE-2018-5146 critical 9.5 An out of bounds memory write while processing Vorbis audio data was reported through the Pwn2Own contest. This vulnerability affects Firefox < 59.0.1, Firefox ESR < 52.7.2, and Thunderbird < 52.7. archsusedebian
CVE-2018-5153 critical 9.5 If websocket data is sent with mixed text and binary in a single message, the binary data can be corrupted. This can result in an out-of-bounds read with the read memory sent to the originating serve… archdebian
CVE-2018-5188 critical 9.5 Memory safety bugs present in Firefox 60, Firefox ESR 60, and Firefox ESR 52.8. Some of these bugs showed evidence of memory corruption and we presume that with enough effort that some of these could… archsusedebian
CVE-2018-18344 critical 9.5 multiple issues in chromium archdebian
CVE-2018-5168 critical 9.5 Sites can bypass security checks on permissions to install lightweight themes by manipulating the "baseURI" property of the theme element. This could allow a malicious site to install a theme without… archdebian
CVE-2018-0202 critical 9.5 clamscan in ClamAV before 0.99.4 contains a vulnerability that could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. The vulnerability is… archsusedebian
CVE-2018-1000085 critical 9.5 ClamAV version version 0.99.3 contains a Out of bounds heap memory read vulnerability in XAR parser, function xar_hash_check() that can result in Leaking of memory, may help in developing exploit cha… archsusedebian
CVE-2018-18336 critical 9.5 multiple issues in chromium archdebian
CVE-2018-12387 critical 9.5 A vulnerability where the JavaScript JIT compiler inlines Array.prototype.push with multiple arguments that results in the stack pointer being off by 8 bytes after a bailout. This leaks a memory addr… archsusedebian
CVE-2018-10528 critical 9.5 An issue was discovered in LibRaw 0.18.9. There is a stack-based buffer overflow in the utf2char function in libraw_cxx.cpp. archdebian
CVE-2018-12363 critical 9.5 A use-after-free vulnerability can occur when script uses mutation events to move DOM nodes between documents, resulting in the old document that held the node being freed but the node still having a… archsusedebian
CVE-2018-12358 critical 9.5 Service workers can use redirection to avoid the tainting of cross-origin resources in some instances, allowing a malicious site to read responses which are supposed to be opaque. This vulnerability … archsusedebian
CVE-2018-12362 critical 9.5 An integer overflow can occur during graphics operations done by the Supplemental Streaming SIMD Extensions 3 (SSSE3) scaler, resulting in a potentially exploitable crash. This vulnerability affects … archsusedebian
CVE-2018-18494 critical 9.5 A same-origin policy violation allowing the theft of cross-origin URL entries when using the Javascript location property to cause a redirection to another site using performance.getEntries(). This i… archsusedebian
CVE-2018-12373 critical 9.5 dDecrypted S/MIME parts hidden with CSS or the plaintext HTML tag can leak plaintext when included in a HTML reply/forward. This vulnerability affects Thunderbird < 52.9. archsusedebian
CVE-2018-18501 critical 9.5 Mozilla developers and community members reported memory safety bugs present in Firefox 64 and Firefox ESR 60.4. Some of these bugs showed evidence of memory corruption and we presume that with enoug… archsusedebian
CVE-2018-12385 critical 9.5 A potentially exploitable crash in TransportSecurityInfo used for SSL can be triggered by data stored in the local cache in the user profile directory. This issue is only exploitable in combination w… archsusedebian
CVE-2018-6088 critical 9.5 multiple issues in chromium arch
CVE-2018-5157 critical 9.5 Same-origin protections for the PDF viewer can be bypassed, allowing a malicious site to intercept messages meant for the viewer. This could allow the site to retrieve PDF files restricted to viewing… archdebian
CVE-2018-1057 critical 9.5 On a Samba 4 AD DC the LDAP server in all versions of Samba from 4.0.0 onwards incorrectly validates permissions to modify passwords over LDAP allowing authenticated users to change any other users' … archdebian
CVE-2018-6089 critical 9.5 multiple issues in chromium arch
CVE-2018-5159 critical 9.5 An integer overflow can occur in the Skia library due to 32-bit integer use in an array without integer overflow checks, resulting in possible out-of-bounds writes. This could lead to a potentially e… archdebian
CVE-2018-18640 critical 9.5 multiple issues in gitlab arch
CVE-2018-6117 critical 9.5 multiple issues in chromium arch
CVE-2018-17468 critical 9.5 multiple issues in chromium arch
CVE-2018-6097 critical 9.5 multiple issues in chromium arch
CVE-2018-5182 critical 9.5 If a text string that happens to be a filename in the operating system's native format is dragged and dropped onto the addressbar the specified local file will be opened. This is contrary to policy a… archdebian
CVE-2018-5172 critical 9.5 The Live Bookmarks page and the PDF viewer can run injected script content if a user pastes script from the clipboard into them while viewing RSS feeds or PDF files. This could allow a malicious site… archdebian
CVE-2018-17469 critical 9.5 multiple issues in chromium arch
CVE-2018-17466 critical 9.5 multiple issues in chromium archsusedebian
CVE-2018-6095 critical 9.5 multiple issues in chromium arch
CVE-2018-5179 critical 9.5 multiple issues in chromium arch
CVE-2018-18339 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18350 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18359 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18356 critical 9.5 multiple issues in chromium archdebiansuse
CVE-2018-18352 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18357 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18348 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18343 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18355 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18354 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18347 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18338 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18353 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18351 critical 9.5 multiple issues in chromium archdebian
CVE-2018-18337 critical 9.5 multiple issues in chromium archdebian